Author Topic: Bad webscript on website - potential problems found...  (Read 848 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Bad webscript on website - potential problems found...
« on: June 02, 2019, 02:36:21 PM »
See security improvement recommendations;
https://webhint.io/scanner/6c710a69-c0d4-4bf6-af0a-8ece080a6a3a#category-Security
Security Checks for -www.fulbacho.net
(3) Susceptible to man-in-the-middle attacks
(5) Domain at risk of being hijacked
(2) Emails can be fraudulently sent
DNS is susceptible to man-in-the-middle attacks
See: https://app.upguard.com/#/www.fulbacho.net
retirable script libraries: https://retire.insecurity.today/#!/scan/7e94e6b03b48bd20472d68cafadc3f6418e7924561f3b75c66b6e2af7d1329ae
not given there but with various DOM-XSS issues:
Results from scanning URL: -https://www.fulbacho.net/libs/marker-clusterer/src/markerclusterer.js
Number of sources found: 408
Number of sinks found: 266

Scanned: https://aw-snap.info/file-viewer/?protocol=secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=d3d3LmZ1bGJ8XmhdLm57dGBsW2JzYG18fWt7fS1ebHVzdHt9e31gc31eYG18fWt7fV5sdXN0e317fS5qcw%3D%3D~enc
URLs that redirect found in: -https://www.fulbacho.net/libs/marker-clusterer/src/markerclusterer.js

1: -http://fc.webmasterpro.de/counter.php?name=browserupdate&style=none -> https://fc.webmasterpro.de/counter.php?name=browserupdate&style=none
2: -http://fc.webmasterpro.de/as_noscript.php?name=browserupdate -> https://fc.webmasterpro.de/as_noscript.php?name=browserupdate

TLS Recommendations
HTTPS mixed content found. Your HTTPS website is referring to an HTTP resource:
-http://google-maps-utility-library-v3.googlecode.com/svn/tags/markerclusterer/1.0/src/markerclustere... on
-https://www.fulbacho.net/
-http://google-maps-utility-library-v3.googlecode.com/svn/tags/markerclusterer/1.0/src/markerclustere... on
-https://www.fulbacho.net/404testpage4525d2fdc  -> https://censys.io/ipv4/188.166.117.135

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!